<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE as a hosted NAC solution in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-as-a-hosted-nac-solution/m-p/3939943#M456508</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I have come across a distributed ISE design where the ISE deployment is provided as a hosted NAC solution for a client.&lt;/P&gt;&lt;P&gt;Question is, the ISE servers will have a FQDN from the host company but the certificates issued by the customer's CA will have their DNS/Domain appended to it. How would ISE will match this certificate and accepts it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;As far as I know ISE will look into the SAN extension of the Cert and if the SAN contains one or more DNS names, then one of the DNS names must match the FQDN of the Cisco ISE node.&lt;/P&gt;&lt;P&gt;In this case the SAN extension within the certificate will only have the customer DNS details and not the host company.&lt;/P&gt;&lt;P&gt;How would we get around this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 14 Oct 2019 05:37:07 GMT</pubDate>
    <dc:creator>AMNassiri0210</dc:creator>
    <dc:date>2019-10-14T05:37:07Z</dc:date>
    <item>
      <title>ISE as a hosted NAC solution</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-as-a-hosted-nac-solution/m-p/3939943#M456508</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I have come across a distributed ISE design where the ISE deployment is provided as a hosted NAC solution for a client.&lt;/P&gt;&lt;P&gt;Question is, the ISE servers will have a FQDN from the host company but the certificates issued by the customer's CA will have their DNS/Domain appended to it. How would ISE will match this certificate and accepts it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;As far as I know ISE will look into the SAN extension of the Cert and if the SAN contains one or more DNS names, then one of the DNS names must match the FQDN of the Cisco ISE node.&lt;/P&gt;&lt;P&gt;In this case the SAN extension within the certificate will only have the customer DNS details and not the host company.&lt;/P&gt;&lt;P&gt;How would we get around this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2019 05:37:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-as-a-hosted-nac-solution/m-p/3939943#M456508</guid>
      <dc:creator>AMNassiri0210</dc:creator>
      <dc:date>2019-10-14T05:37:07Z</dc:date>
    </item>
    <item>
      <title>Re: ISE as a hosted NAC solution</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-as-a-hosted-nac-solution/m-p/3940079#M456510</link>
      <description>Depends on what are you using the certificate for. If its for EAP&lt;BR /&gt;communication, its not necessary to have the fqdn in the cn or alternative&lt;BR /&gt;domains. But if you are using it for administration login then (admin or&lt;BR /&gt;guest portal) then its a must to avoid certs errors. So it depends on the&lt;BR /&gt;use of the cert&lt;BR /&gt;&lt;BR /&gt;**** remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Mon, 14 Oct 2019 09:54:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-as-a-hosted-nac-solution/m-p/3940079#M456510</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2019-10-14T09:54:52Z</dc:date>
    </item>
    <item>
      <title>Re: ISE as a hosted NAC solution</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-as-a-hosted-nac-solution/m-p/3940493#M456511</link>
      <description>&lt;P&gt;Thanks Mohammed,&lt;/P&gt;&lt;P&gt;The cert will be used for EAP-TLS and Portals (Guest, BYOD, Sponsor, Self-Registered Guest).&lt;/P&gt;&lt;P&gt;How do we go around this for the portals then?&lt;/P&gt;&lt;P&gt;The way I have done the CSR in the past with on-premise deployment (customer owned and managed ISE solution) is like:&lt;/P&gt;&lt;P&gt;CN=CompanyA-ISE&lt;/P&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;SAN&amp;nbsp; = DNS name - ISE1.company1.local&lt;/LI&gt;&lt;LI&gt;SAN&amp;nbsp; = DNS name - ISE2.company1.local&lt;/LI&gt;&lt;LI&gt;SAN = IP Address 10.x.x.1&lt;/LI&gt;&lt;LI&gt;SAN = IP Address 10.x.x.2&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;P&gt;Now the CSR with the managed solution will have the DNS entry of the host-company and not customer's, I&amp;nbsp;do not know how this would work?&lt;/P&gt;&lt;P&gt;Is there anything the customer can do on their infrastructure like within the CA to include the host company's DNS details etc.?&lt;/P&gt;&lt;P&gt;Appreciate any input.&lt;/P&gt;&lt;P&gt;Thanks.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2019 22:59:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-as-a-hosted-nac-solution/m-p/3940493#M456511</guid>
      <dc:creator>AMNassiri0210</dc:creator>
      <dc:date>2019-10-14T22:59:01Z</dc:date>
    </item>
    <item>
      <title>Re: ISE as a hosted NAC solution</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-as-a-hosted-nac-solution/m-p/3948049#M456514</link>
      <description>Here is info on ISE certificates, ISE will need to have the correct FQDN and/or IP addresses for correct DNS resolution. its not meant to deploy for hosted solution but perhaps you could setup a portal for different customers and under each portal create a different certificate? and separate certificate per PSN?&lt;BR /&gt;Look at Certificate group tag, use one per customer and per portal? &lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_0111.html#task_9232D7F51A5241D28DA88F123CB63EED" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_0111.html#task_9232D7F51A5241D28DA88F123CB63EED&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;The certificate is assigned under the portal settings. you could do a different &lt;BR /&gt;&lt;BR /&gt;some other info&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://cs.co/ise-guides" target="_blank"&gt;https://cs.co/ise-guides&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-security-ecosystem-integration-guides/ta-p/3621164#toc-hId-1853178353" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-security-ecosystem-integration-guides/ta-p/3621164#toc-hId-1853178353&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 25 Oct 2019 11:12:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-as-a-hosted-nac-solution/m-p/3948049#M456514</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-10-25T11:12:05Z</dc:date>
    </item>
    <item>
      <title>Re: ISE as a hosted NAC solution</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-as-a-hosted-nac-solution/m-p/3950859#M456515</link>
      <description>&lt;P&gt;Hi Jason,&lt;/P&gt;&lt;P&gt;Thanks for your reply.&amp;nbsp;&lt;/P&gt;&lt;P&gt;ISE is being hosted for only a single client, I should have worded it correctly my apologies. It is managed by a third party in their network for this client.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So that is why the DNS and FQDN questions arised, whose to use.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are trying to add the DNS entries of the the managed services team into clients domain (which is again managed by a third party) so ISE can resolve it. This is work in progress and I will keep you posted.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again for your time and the links attached.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2019 02:35:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-as-a-hosted-nac-solution/m-p/3950859#M456515</guid>
      <dc:creator>AMNassiri0210</dc:creator>
      <dc:date>2019-10-31T02:35:37Z</dc:date>
    </item>
  </channel>
</rss>

